nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0230 CVE-2022-0230
MEDIUM
Better WordPress Google XML Sitemaps <= 1.4.1 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2022-0230 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Better WordPress Google XML Sitemaps (support Sitemap Index, Multi-site and Google News) | CVE List | 1.4.1 to ≤ 1.4.1 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2022-0230Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2022-0230Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/c73316d2-ae6a-42db-935b-b8b03a7e4363